Skip to content

/us-sox-expert

Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations,

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-sox-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/us-sox-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations,

SKILL.md

us-sox-expert.SKILL.md
name: us-sox-expert
description: Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations, Development), entity-level controls, IT-dependent manual controls, deficiency evaluation, SOC 1 vendor reliance, and the SEC/PCAOB/DOJ enforcement triangle.
allowed-tools: Read, Glob, Grep, Write

Sarbanes-Oxley Act of 2002 (SOX) Expert

Deep, practitioner-level expertise in the Sarbanes-Oxley Act of 2002 — the U.S. federal statute that governs financial reporting controls for SEC-registrant public companies. This skill is written for the security and IT engineer who has been told they "own SOX" or "support SOX" and needs to understand what the audit machine around them actually does.

Framework identity

  • **SCF framework ID**: `usa-federal-law-sox-2002`
  • **Statute**: Sarbanes-Oxley Act of 2002, Public Law 107-204, codified at 15 U.S.C. §§ 7201 et seq. (criminal provisions in 18 U.S.C. §§ 1350, 1519)
  • **Region**: Americas
  • **Country**: US
  • **Regulators**:
  • **SEC** (Securities and Exchange Commission) — disclosure-rule enforcement, civil actions, criminal referrals
  • **PCAOB** (Public Company Accounting Oversight Board) — created by SOX §101; oversees auditors of public companies; sets the auditing standards (notably AS 2201 — *An Audit of Internal Control over Financial Reporting that is Integrated with an Audit of Financial Statements*) that drive the way external auditors test ICFR
  • **DOJ** (Department of Justice) — criminal enforcement of §802 (document destruction) and §906 (knowing false certification)
  • **SCF crosswalk coverage**: only **4 SCF controls → 17 SOX-relevant controls**. That number is small for a reason — see "Why the SCF mapping is thin" below.

Framework in plain language

SOX is the U.S. response to the Enron and WorldCom accounting frauds of 2001–2002. It does **not** prescribe specific cybersecurity controls. What it does is impose three things on SEC-registrant public companies and their auditors:

1. **Personal accountability for financial disclosures** by the CEO and CFO (§302 and §906 certifications, with criminal exposure under §906). 2. **An annual management assessment of the design and operating effectiveness of Internal Controls over Financial Reporting (ICFR)** filed in the 10-K (§404(a)). 3. **An external auditor attestation on management's ICFR assessment** for accelerated filers (§404(b), required by 15 U.S.C. § 7262(b)).

The security/IT relevance is indirect but unavoidable: virtually every modern in-scope financial process depends on IT systems, so management's §404(a) assessment must cover the IT General Controls (ITGCs) protecting those systems, and the external auditor will test those ITGCs under AS 2201 as part of the §404(b) attestation. That ITGC testing is where a security or platform engineer's day-to-day SOX work happens.

Why this plugin frames SOX as a governance-over-ICFR layer

The SCF crosswalk maps only **4 SCF controls** to SOX. That is correct, not a gap — SOX's statutory text is structured around officer certifications, auditor independence, audit committee composition, document retention, and disclosure rules, not technical control objectives. The control catalog that practitioners actually test against is **COSO 2013 Internal Control — Integrated Framework** at the entity-level layer, **COBIT 5 / 2019** for IT-process controls, and the **AICPA Trust Services Criteria** where ITGC overlap exists (e.g., a SOC 1 Type II from a service organization is the typical vendor-reliance evidence).

So SOX's role in this plugin is **the governance and accountability frame**:

  • §302 + §906 = personal certification (the "tone at the top" forcing function)
  • §404(a) = management assessment of ICFR (forces a control inventory, scope, walkthrough, and test program)
  • §404(b) = external auditor attestation (forces independent reperformance of that test program for accelerated filers)
  • §802 = document retention with criminal teeth
  • §409 = real-time material-event disclosure (8-K within 4 business days)

The actual control objectives flow from COSO + COBIT + the auditor's own internal control workpaper templates. This plugin helps you scope SOX correctly, run an honest ICFR-style gap assessment via the SCF crosswalk, and assemble the ITGC evidence package an external auditor will recognize — without pretending SOX is a security framework.

Territorial scope and applicability

Who must comply

Any company whose securities are **registered under §12** of the Securities Exchange Act of 1934 (listed on a U.S. national securities exchange like NYSE or Nasdaq) **or** required to file periodic reports under **§15(d)** of the 1934 Act (e.g., issuers with publicly registered debt). In short: **U.S.-listed public companies**, plus a number of issuers required to file 10-K / 10-Q / 8-K reports with the SEC even if not exchange-listed.

Foreign private issuers

A non-U.S. company with securities listed on a U.S. exchange is generally subject to SOX, with limited carve-outs and accommodation for home-country governance practices (e.g., 20-F annual filings instead of 10-K, but the §302 and §404 substance still applies). Don't assume "we're headquartered abroad" gets you out of SOX scope.

Private companies in the SOX runway

Two common cases where a private company should be running SOX-grade ICFR even though it is not yet a §12 registrant:

  • **Pre-IPO (S-1 readiness)** — once the S-1 lands, the company effectively needs §404(a)-quality ICFR documentation in place; underwriters, auditors, and the SEC review team will probe it. Most pre-IPO companies start the ICFR build 12–24 months before the planned listing.
  • **Acquisition by a public company** — once acquired, the target's financially significant systems becom
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked